Vulnerability record · CVE-2020-25079 · published 2 September 2020
CVE-2020-25079: D-Link DCS cameras authenticated command injection in ddns_enc.cgi
Dlink · Dcs 4703e Firmware
D-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user with valid credentials can inject OS commands through that endpoint, giving full control of the camera's underlying system. The record lists additional DCS firmware products, but the description only confirms the two camera models.
Description
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote command execution with high impact, is in CISA KEV with a 99th-percentile EPSS score, and has public exploit references, though it requires valid credentials.
What it is
D-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user with valid credentials can inject OS commands through that endpoint, giving full control of the camera's underlying system. The record lists additional DCS firmware products, but the description only confirms the two camera models.
Impact
An authenticated attacker gains arbitrary command execution on the device, leading to full compromise of confidentiality, integrity and availability (CVSS 3.1 base 8.8). This can expose video feeds, credentials and the camera as a pivot point into the network.
Attack surface
Reachable over the network via the web management interface at cgi-bin/ddns_enc.cgi; the CVSS vector (AV:N/PR:L/UI:N) indicates a low-privileged authenticated account is required and no user interaction is needed.
Exploitation
CVE-2020-25079 is listed in CISA KEV (added 2025-08-05, due 2025-08-26) and has a high EPSS 30-day probability of 0.56317 (99th percentile), and a reference is tagged Exploit, indicating public exploit activity. No ransomware campaign use is documented.
What to do
- Apply the D-Link vendor fix per SAP10180: update DCS-2530L to 1.06.01 Hotfix or later and DCS-2670L beyond 2.02; if no fix is available for a listed model, discontinue use as CISA advises.
- Restrict camera web management access to a trusted management VLAN or VPN; never expose cgi-bin endpoints to the internet.
- Change default and weak credentials, enforce unique strong passwords, and remove unused accounts to limit the low-privileged access the flaw requires.
- Monitor D-Link advisories and CISA KEV for updated affected-model and patch information, since the record lists more DCS firmware products than the description confirms.
- If patching is not possible, isolate affected cameras on a segmented network with egress filtering to reduce pivot and exfiltration risk.
Detection
- Inspect web/proxy and camera logs for requests to cgi-bin/ddns_enc.cgi, especially with shell metacharacters (;, |, `, $(), &&) in parameters.
- Alert on unexpected outbound connections or processes spawned by the camera's web server (e.g., shell, wget, curl, nc) after ddns_enc.cgi access.
- Hunt for anomalous authenticated sessions on camera management interfaces, including logins from unusual source IPs followed by ddns_enc.cgi requests.
- Baseline camera firmware versions and flag DCS-2530L below 1.06.01 Hotfix and DCS-2670L at or below 2.02.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-25079 to the Known Exploited Vulnerabilities catalog on 5 August 2025 as "D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 August 2025.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 | PatchVendor Advisory |
| https://twitter.com/Dogonsecurity/status/1271265152118259712 | Broken LinkExploitThird Party Advisory |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 | PatchVendor Advisory |
| https://twitter.com/Dogonsecurity/status/1271265152118259712 | Broken LinkExploitThird Party Advisory |
| https://support.dlink.com/productinfo.aspx?m=DCS-2530L | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25079 | US Government Resource |
Track CVE-2020-25079 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-25079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.